What a QuickBooks MCP connector cannot do (and should not).
It should not auto-post. It should not let a prompt turn off human approval. It should not pretend it can mark a QBO rec done. It should not read Intuit’s bank-feed API (there isn’t one you can use that way). It should not keep generated files forever, attach the client’s source PDFs to a period report, or spend five days pulling statements. Product-level exclusions (no permanent deletes, no platform settings, no payments, no payroll filings) live on features. This is the close-ops list we wrote down after watching real SOPs assume the opposite.
The structural cannot-dos live on the features page.
Firms evaluating a QuickBooks MCP connector ask for a feature list. Fractional CFOs ask whether they can finally connect Claude to multiple QBO clients instead of tab-switching four entities. The useful document is the refuse list. Below is what the connector will not do in a real close, including the things people ask for in the first month and should stop asking for.
It should not auto-post. It should not let a prompt turn off human approval. It should not pretend it can mark a QBO rec done. It should not read Intuit’s bank-feed API (there isn’t one you can use that way). It should not keep generated files forever, attach the client’s source PDFs to a period report, or spend five days pulling statements. Product-level exclusions (no permanent deletes, no platform settings, no payments, no payroll filings) live on features. This is the close-ops list we wrote down after watching real SOPs assume the opposite.
If a vendor says yes to all of this and “we’ll have it in six months,” believe the six months. I would rather tell you no in the first conversation.
Numbers Game structurally cannot:
- Permanently delete ledger records (void or mark inactive only).
- Change Intuit or Xero platform settings.
- Initiate payments or ACH.
- Touch payroll filings.
- Convert currency.
Tool-level exclusions, not policy promises. Read them on featuresand security. Do not retype them into a proposal as if they were roadmap items we are being modest about.
What follows is month-end work: the jobs a close SOP tries to hand the connector, and the honest answers. An outsourced CFO month-end close hits the same list. The audit-before-you-model offer only holds if the audit cannot mutate the file.
No auto-post. Not as a default, not as a favor.
The model proposes. A person approves. Then the write hits QuickBooks Online or Xero.
That sentence is the product. It is also the sentence firms try to bargain with once they trust the first twenty entries. I get it. Close week is long. The first batch looked right. The temptation is to skip the click.
A recurring amortization is the usual test. The SOP says “set up the schedule and post every month.” What the connector can do is draft twelve months of amortization in one pass, hold them for approval, and let you approve the set. What it cannot do is become a silent recurring poster. An amortization schedule plus a recurring task is a reminder. The entries are still drafted and approved.
Same for bank coding, AJEs, vendor bills, invoices. Throughput tactics (rules, templates, batch, import) are in the faster transaction entry guide. None of those tactics is “the model posted while you were at lunch.”
If you want a categorizer that posts unattended, you are shopping in a different aisle. We are not competing there. We built this inside AG Accounting because we still sign the books.
The approval rail turns off if you tell it to.
Firms skip this note because it sounds like we are scolding their SOP. I am not scolding. I am telling you how precedence works, because it will bite you.
A firm instruction that says “post it and tell me after” is not a productivity hack. It is a request to switch off approval-before-write. Do not write that sentence. Restate the approval rules on purpose in the firm section, even though they already exist in the product. Precedence means your section wins. If your section says skip approval, you have used precedence to disable the control you are about to describe to a client.
Treat the rail like a period lock:
- Proposed writes show net debits and credits.
- A person with the right role approves.
- The QBO audit trail shows the action under the connected path you authorized, not under a mystery “AI user” you cannot name in peer review.
- Viewers cannot write. See roles and access.
Fractional CFO work (audit the file, then model) only holds if the audit cannot mutate the file on a vibe. Advisory shops should care about this more, not less. You often did not keep these books.
Connecting Claude to multiple QBO clients is not tab-switching.
Native one-company Claude-to-QBO is not a substitute for a firm connector. It is a toy. One Claude account, one QuickBooks company. Firms still alt-tab. A fractional CFO with four entities still signs into four files. Parallel sessions across the book do not exist. QuickBooks’ own AI has the same file-scale limit.
What the connector can do: one Claude (or ChatGPT) organization, one Numbers Game account, one project per client, live QBO or Xero on each. That is how you connect Claude to multiple QBO clients without mixing the books.
What it cannot do: dump four unrelated entities into one project and “just be careful.” Combined reporting is for related companies only. Combined is not consolidated. Firm controls are on the MCP page, vs QuickBooks AI, and multi-entity reporting.
If a demo promises that one chat can see every client at once, ask what happens when the model books a journal into the wrong company. Quiet mistakes are expensive. One project per client is the refuse that prevents them.
Generated files expire. Plan for that.
Close reports, PDFs, and download links are temporary. Expect something on the order of an hour to 24 hours, depending on the artifact. Generated PDFs auto-delete 24 hours after creation. Stated on client reporting.
Save the issued package in the client folder (SharePoint, TaxDome, Drive) the same day. If you need the report inside Numbers Game for next month’s comparison, use the explicit save-report path, with a retention setting you chose. A Claude download link is not the workpaper. The link will die. The client will still have questions in week three, usually on a Thursday, usually about a number you cannot re-open from a dead link. A 13-week cash PDF with a dead link is not a board pack.
If your SOP says “attach the close report to the QBO period,” read the next section before you promise it.
It can attach files it generated. It cannot attach the client’s source docs to a period report.
Two jobs get collapsed in SOPs. They should not be.
Job 1. Claude generated a PDF (a rec report, a close summary). The connector can attach files it generated, in the places QBO will accept an attachment, which is usually a transaction. A period-level close report has no QBO transaction to hang on. There is nowhere to put it. Save it in the client folder.
Job 2. The client emailed a lease, a Ramp receipt, a board deck. You want that source document on the JE. Plaid will not carry supporting documents. A bank line that arrived through an aggregator is attachment-blind. Google Drive, Ramp, a shared inbox: still your document system. The connector is not.
If the close SOP says “pull source docs from the client and attach them to every JE,” you will spend the month in Drive. Budget that. Do not write it as a connector step.
Void is not undo-everything.
Void exists for a subset of documents (invoices and payments, in the cases we document). Other documents have to be corrected in place. The connector cannot permanently delete ledger records. That is the feature, not a missing button.
SOPs that say “if it’s wrong, void it and repost” fail on bills, journals, and a long tail of QBO objects. Write the actual correction path: reverse with a dated JE, edit in place, or leave it and disclose. Guessing “void” is how you get a half-applied delete and a support thread at 9pm.
There is no QBO bank-feed API for the connector to read.
This is the one that surprises people who thought “connected to QuickBooks” meant “we have the feed.”
Intuit does not give you an open bank-feed API the connector can sit on. We cannot pipe pending QBO feed lines into Claude the way a screenshot of the Banking tab looks. Other tools hit the same wall. It is not a Numbers Game-only gap. I wish it were, because then we could fix it.
Workarounds that exist in real firms:
- Let QBO drop the feed to Uncategorized (or a clearing account you named). Claude reviews Uncategorized, proposes recodes, a person approves. Aiming for most of the book on that path is reasonable. Aiming for 100% is how you get equity plugs.
- Import a CSV or a statement PDF you already pulled. The import rows that posted can be kept with what they posted to.
- Optional Plaid (or similar) for transaction data. Optional means optional. Some firms do not want banks connected that way. CSV must remain. Plaid is also attachment-blind: you get the line, not the receipt.
Bank-feed controls when you are coding activity (propose-only default, confidence outside the model, structural holds) are a different page: AI bank feed and bank transactions to Claude. Do not confuse those controls with “we read QBO’s bank feed API.” We do not.
A rec report is not “marked reconciled” in QuickBooks.
The QBO API cannot mark transactions reconciled the way the Banking or Reconcile screen does. The connector can produce the rec report: statement balance, book balance, named differences. A person still completes the rec in QBO if you need the green check the client has been trained to look for.
Write the SOP to match:
- Claude: match statement to book, name the gaps, propose missing entries.
- Person: approve entries, then finish the rec in QBO if the file’s process requires the native status.
- Do not instruct the model to “mark it reconciled.” It will either fail or lie.
Same family as payroll: we can help you reconcile a payroll journal to the GL. We do not touch payroll filings. Do not merge those sentences.
It will not spend five days pulling statements.
A CPA firm running dozens of QBO files still loses the better part of a week to “everyone go get the statements.” A fractional CFO with eight to forty files still waits on the same pile, just with fewer people to fetch it. SharePoint fills up. The hosted bookkeeper used to wait on that pile. The connector does not log into the bank. I cannot make that sound nicer than it is.
Honest options:
- The client (or the team) still pulls statements. Save them in the folder the skill expects. Claude reads what you saved.
- Where a bank connection exists through the optional path, you get transactions, not a PDF statement, and not the attachments.
- Close GL-only when the statement is late, and say so. Do not recon against a missing file.
If a demo promises that statements arrive by themselves, ask which login is doing the arriving. If the answer is “the AI,” you are hearing a hope. We will tell you no. Firms have asked us to say no more often than they admit, after a vendor said yes for six months.
Word templates, row shading, and other close-ops theater.
The connector will not ingest Close_Report_TEMPLATE.docx. It will not preserve per-row shading, your partner’s favorite font, or the yellow cells on the review tab. Produce numbers. Drop them into the template you already own, or use branded statements from the live ledger (client reporting). Fill the 13-week tab. Do not let the model redesign it.
Related refuses:
- It will not email the package to the client’s customer on its own. Document sending is gated on purpose.
- It will not run QuickBooks Desktop, Sage 50, Rillet, or ProConnect. Those are named gaps. ChatGPT works as the model. Gemini does not (no MCP). Scheduling overnight jobs is Claude scheduled tasks today.
What you should put in the SOP instead of a wish.
Replace each cannot-do with a next action the team can actually finish.
| SOP wish | What to write instead |
|---|---|
| Post the amortization every month | Draft 12 months, approve the set, reminder for next year |
| Attach the close report to QBO | Save the PDF in the client folder the same day |
| Mark the rec done | Rec report, then a person finishes in QBO |
| Pull every statement | Folder drop, or GL-only, or optional bank connection for lines not PDFs |
| Void and repost | Reverse or correct in place; void only where QBO allows |
| Use the Word template | Numbers out, template in the DMS |
| One chat for four QBO entities | One project per entity; combined reporting only if related |
| Post and tell me after | Delete that sentence |
The monthly runbook that uses these constraints is the close how-to in this series. The failure modes if you skip them are the companion post on what AI gets wrong.
Cannot-do questions, answered.
Book a walkthrough and bring the wish list.
Bring the close SOP that currently says the tool will handle it. We will mark the cannot-dos on a live QBO or Xero file.